Pideeco
}
AMLPSD3fraudePSRspoofingBelgiqueMembers

Fraud & AML in 2026: how PSR shifts fraud liability onto banks

PSR shifts fraud reimbursement onto banks and reverses the burden of proof. What changes, when, and the Belgian exposure in 2026.

Camille Crouzet13 September 20269 min read50

On August 3, 2026, Visa announced the acquisition of BioCatch for $2.4 billion in cash. Earlier that year, the final compromise PSR/PSD3 texts, published on 23 April 2026 and still awaiting formal adoption, locked in a principle Belgian banks will have to get used to: in cases of spoofing, it's the banks that refund customers in full. Between RegTech market consolidation and the arrival of AI-driven monitoring in AML surveillance rooms, fraud detection has stopped being a cost center — it has become the top line-item risk to earnings.

Three converging events are redefining the fraud/AML equation in 2026. First, consolidation: Visa is absorbing BioCatch ($2.4B in cash), the behavioral biometrics leader that protects 760 million users across more than 350 financial institutions, in response to estimated global losses exceeding $1 trillion a year. Second, regulation: the PSR reverses the burden of proof — in cases of bank-employee identity spoofing, the refund is full, and it's the bank that must prove the customer's gross negligence, with a much higher evidentiary bar than under PSD2.

For Belgian banks, the combination is brutal: €93 million diverted through phishing in 2025 (versus €49 million in 2024), a 75% blocking rate that will need to climb, and a VoP (verification of payee) that will extend to all currencies and rails. Those still treating fraud as an IT issue need to plan now, ahead of general PSR application.

Why the fight against fraud is losing the race

undraw_data-thief_d66l (1)

BioCatch's own assessment, from its August 3 announcement, is worth quoting: as a company and as an industry, they are not winning this fight — losses, attempt volumes, mule accounts, and victims keep growing every year (in some cases exponentially), everywhere in the world — BioCatch announcement blog, 3 August 2026. Generative AI has industrialized scams: convincing voice deepfakes, phishing campaigns nearly indistinguishable from a real bank email, and sharply reduced attack costs. Visa estimates that scams and account takeovers cost the global economy more than $1 trillion a year.

The detection market is responding through consolidation. After Featurespace was acquired by Worldpay in 2024, it's now BioCatch — owned by funds advised by Permira and other investors — moving under Visa's flag for $2.4 billion in cash, with closing expected by the end of Visa's fiscal Q2 2027, subject to regulatory approvals. The industrial logic is clear: BioCatch brings behavioral detection, Visa brings distribution — 14,500 institutions, 329 billion transactions a year worth more than $17 trillion.

The regulatory framework is shifting in parallel

How is the regulatory framework shifting at the same time?

While payments players consolidate, Brussels is locking in liability. On April 23, 2026, the Council published the final compromise texts for PSD3 and the PSR, with a first-reading agreement targeted with Parliament (source: Council of the EU, document register, ST-8221-2026-INIT [PSR] and ST-8222-2026-INIT [PSD3], 4/23/2026). A reminder of the regulatory mechanics: the PSR is a regulation — directly applicable across all 27 member states without national transposition; PSD3 is a directive, which will need to be transposed. This distinction isn't a technicality for compliance departments: the timeline and implementation burden differ.

The philosophical shift is radical. Under PSD2, security was "technical": two-factor authentication, passwords. Under the PSR, it becomes "ecosystem responsibility": collaboration between actors is no longer optional, and the burden of proof shifts.

What do the new fraud and AML rules mean for financial institutions?

1. The PSR: what actually changes for bank liability

  • Spoofing, first. If a fraudster impersonates a bank employee ("this is the fraud department, transfer your funds to this secure account") and the customer complies, the bank must refund the full amount, provided the customer notified their bank and the police without undue delay. Refusal to reimburse is only possible if the bank proves the customer's fraud or gross negligence — a much higher bar than under PSD2 — and reimbursement may be deferred for up to 15 business days where there is objectively justified suspicion, with a written explanation. In accounting terms: every successful scam involving impersonation of a bank employee becomes a direct cost to the institution, absent difficult-to-establish proof otherwise.

  • Universal VoP, last wave. Verification of payee (Name Check) was until now anchored in the instant payments regulation, limited to SEPA euro transfers. The PSR extends it to all transfers in EU currencies and all rails — but the extended obligation (arts. 50/57) applies about 27 months after entry into force, after general PSR application. The "SEPA safety net" becomes a European shield, in the last wave.

  • Freezing on the receiving end. The beneficiary PSP is now empowered — and required — to act as a safety brake: freezing suspicious incoming funds before they're credited to the beneficiary. This is the main weapon against mule accounts and cash-outs.

  • Platforms enter the liability chain. The most-discussed new element: after reimbursing a customer who fell victim to a scam launched on a social network or through a fraudulent ad, the bank can seek recourse against the platform — provided the platform was notified of the fraudulent content and failed to remove it. Fraud ends up in the banking app, but it often starts on a platform; the regulator has decided to push the cost back to where it originated.

  • Finally, the GDPR safe harbor. PSPs are explicitly authorized to share fraud data: mule account identifiers, device fingerprints, attack patterns. Collective defense consortiums and shared blacklists stop being a compliance risk and become an encouraged tool.

2. Agentic AI and governance: what Santander shows

On transaction monitoring, the often-cited example is Santander, which has used ThetaRay's AI models for years to detect money-laundering patterns invisible to static rules. The useful lesson for a Belgian compliance officer is governance: document features, trace decisions, and prepare answers for inspectors — exactly what AMLA expectations will formalize. A model that "works" without being explainable is a liability time bomb, especially since the PSR makes the bank financially responsible for missed fraud.

3. Market consolidation: fraud detection becomes infrastructure

The 3 August 2026 deal fits Visa's value-added services strategy. After Featurespace/Worldpay in 2024, BioCatch — owned by funds advised by Permira — moves under Visa for $2.4 billion in cash, closing expected by the end of Visa's fiscal Q2 2027, subject to approvals. Andrew Torre, the division's president, sums it up: stop fraud before it reaches the payment stage.

Cohort analysis and fraud detection

For European banks, the signal is competitive: connected to Visa's rails (14,500 institutions, 329 billion transactions a year), BioCatch's model will be fed by unmatched data volume. The question is no longer "should we have behavioral detection?" but "from which vendor, with what dependency and auditability?"

Belgium: €93 million lost to phishing in 2025

The Belgian banking federation Febelfin documents the country's exposure: €93 million was diverted through phishing in 2025, versus €49 million in 2024, while Belgian banks detect, block, or recover roughly 75% of fraudulent transactions from these campaigns. Net losses equal about 0.004% of total transaction volume in 2025: each individual fraud is marginal for the bank; the sum is not. Under the PSR, the remaining 25% becomes a direct cost, on top of full bank-spoofing refunds.

Banking fraud economics: cost balance scale

Belgian phishing exploits trust in institutional channels — fake messages in the National Bank's name, fake advisors. The NBB has had to warn against fake articles using its name. For Belgian institutions, extended VoP and receiving-end freezes are the tools that will cut residual loss — freezes at general PSR application, extended VoP about six months later.

The platform in the crosshairs: the investment-scam precedent

Could social media platforms now become financially liable for fraud?

undraw_social-media-profile_hjh9

The PSR's platform liability principle responds to a massive phenomenon: fake investment ads on social media. The mechanism works as follows: the bank reimburses the victim, then seeks recourse against the platform, which was notified of the fraudulent content and failed to remove it. For Belgian banks, this is a new recovery lever — but it requires setting up rigorous traceability of reports sent to platforms. An undocumented report is a lost recourse.

  • For compliance and AML departments. Transaction monitoring needs to shift from a rules-based logic to a behavioral, predictive one. Concretely: audit false-positive rates, reduce the share of manually processed alerts, and prepare the model-explainability file before AMLA asks for it.

  • For risk and operations departments. Receiving-end freezing is a major process change: it requires fast decision loops to freeze suspicious incoming funds without penalizing legitimate customers, and verification workflows aligned with universal VoP — including for non-SEPA transfers and high-value payments now in scope.

  • For legal departments. Map out spoofing cases and build evidence files: under the PSR, it's the bank that must prove the customer's gross negligence to refuse a refund. Also, set up traceability for reports made to platforms — recourse against them will only exist if the report is documented.

  • For procurement and IT departments. Market consolidation is shrinking the pool of independent behavioral-detection vendors. Multi-year contracts will need to address technology dependency — along with the audit clauses supervisors require for outsourcing.

What are the key takeaways for Belgian banks?

  1. The PSR reverses the burden of proof: in spoofing cases, full reimbursement by the bank, unless the bank proves the customer's gross negligence — a bar considerably raised compared to PSD2 (iPiD).

  2. Receiving-end freezing becomes mandatory at general PSR application; extended VoP (all currencies, all rails) follows about six months later — plan it, don't treat it as an immediate build (iPiD).

  3. Fraud detection is consolidating: Visa/BioCatch at $2.4B following Featurespace/Worldpay — behavioral detection is becoming payment infrastructure, not an option (CNBC).

  4. In Belgium, €93M diverted through phishing in 2025 (versus €49M in 2024) and a 75% blocking rate: the PSR turns the residual 25% into a direct cost for Belgian banks (Febelfin).

Roadmap / Upcoming Timeline

Deadline

Event

Recommended Action

December 2026

European Parliament plenary vote on PSR/PSD3 (indicative date: 14/12/2026), then OJ publication

Finalize impact analysis and monitoring

Q4 2028 (est.)

General PSR application, 21 months after entry into force. Extended payee verification (arts. 50/57) and related liability about 6 months later, i.e. Q2 2029

Non-SEPA VoP, receiving-end freeze, fraud-data sharing

July 10, 2027

Full application of the AMLR — a single AML rulebook across the EU

Align transaction monitoring with AMLA standards; prepare model explainability

January 1, 2028

Start of AMLA's direct supervision of high-risk groups

Large Belgian groups should document their RegTech outsourcing choices now

Are Belgian banks ready for the new economics of fraud?

The message for Belgian banks is clear: fraud can no longer be treated as a purely operational or IT issue. The combination of rising scam volumes, increasingly sophisticated AI-enabled attacks, stricter PSR liability rules and rapid consolidation in fraud-detection technology is changing the economics of fraud fundamentally.

The Visa/BioCatch acquisition illustrates where the market is heading: behavioral analytics and AI-driven detection are becoming core components of payment infrastructure. At the same time, the PSR will place greater financial responsibility on PSPs, particularly in spoofing and scam cases, while expanding Verification of Payee and strengthening controls around suspicious payments.


For banks, the priority should therefore be to move from reactive fraud management to proactive fraud prevention. This means investing in behavioral detection, strengthening VoP and receiving-side controls, improving fraud-data sharing, and ensuring that automated models are explainable, auditable and properly governed.

undraw_multitasking_i2bv

The regulatory timeline leaves little room for complacency. Institutions that start adapting now can turn these changes into an opportunity to reduce fraud losses, strengthen customer protection and build a more resilient control framework. Those that wait until the new obligations take effect may find themselves managing not only higher fraud volumes, but also significantly higher financial and regulatory exposure.

Members-only content

This article is exclusive to registered Pideeco members. Create a free account to read it - no credit card required.

Create a free accountAlready have an account?Sign in
Camille

Written by

Camille Crouzet

Consultant at Pideeco - supporting financial institutions on AML, KYC and regulatory transformation.

Found this article on AML helpful?

Our specialists are ready to help you tackle complex compliance and risk challenges.